Arbitrary File Write Vulnerability in Electerm FTP/SFTP Client
CVE-2026-73225
8.1HIGH
What is CVE-2026-73225?
The Electerm open-source terminal client suffers from an arbitrary file write vulnerability that allows malicious FTP or SFTP servers to exploit recursive transfers. This occurs due to insufficient sanitization of user-supplied values in file transfers, enabling attackers to write potentially harmful content outside the designated download directory. The issue has been addressed in version 3.15.120, emphasizing the importance of keeping software up to date to protect against vulnerabilities.
Affected Version(s)
electerm < 3.15.120
